Microsoft 365 Endpoint Administrator flashcards
130 free flashcards. Tap a card to flip it.
Android Enterprise Fully Managed
Flip cardAn Intune enrollment type for corporate-owned Android devices that provides full device control, separating work and personal data, and restricting app installations to approved sources.
- Designed for corporate-owned, single-purpose, or dedicated devices.
- IT has full control over the entire device.
- App installations are restricted to the Managed Google Play Store.
Memory trick: Fully managed locks down the whole device for the company.
Intune macOS PKG Deployment
Flip cardIntune's method for deploying macOS applications packaged as .pkg files, enabling silent installation and proper handling of administrative privileges.
- Uses the 'macOS app (DMG, PKG, APP)' app type
- Supports silent installation of .pkg files
- Handles apps requiring administrative privileges
Memory trick: Mac Apps Need Specific Paths, From Web to Package.
Intune macOS LOB App Deployment (.PKG)
Flip cardThe method in Microsoft Intune for deploying custom macOS applications packaged as .PKG files, often used for internal or non-App Store apps.
- Supports .PKG file format.
- Used for custom or internal applications.
- Can be assigned as 'Required' for mandatory installation.
Memory trick: LOB .PKG is the custom key for mandatory macOS installs.
Automatic MDM Enrollment (Azure AD Join)
Flip cardA feature in Azure Active Directory that automatically enrolls Windows devices into Microsoft Intune when they are joined to Azure AD by a user.
- Configured in Azure AD > Mobility (MDM and MAM).
- Activates when a user joins a device to Azure AD.
- Requires MDM user scope to be set to 'Some' or 'All'.
Memory trick: Auto-Enrollment is like a digital 'welcome wagon' from Azure AD to Intune.
Intune Device Restrictions (Windows)
Flip cardA configuration profile in Microsoft Intune used to control various settings and features on Windows devices, including restricting application installation sources.
- Manages device features and user experiences.
- Can restrict app store access and installation of unapproved apps.
- Applied to groups of users or devices.
Memory trick: Device restrictions lock down your app options.
Intune LOB App (Windows)
Flip cardA Microsoft Intune application type used to deploy standard Windows installer packages (.msi, .appx, .msix) directly to managed Windows devices.
- Supports silent installation for .msi files.
- Ideal for custom or internal applications.
- Requires direct upload of the installer file.
Memory trick: Many Devices Deploy Apps, Like Intune's Big Options.
Intune Win32 App
Flip cardA Microsoft Intune application type used for deploying complex Windows applications, including those with multiple files, custom scripts, and advanced detection methods.
- Requires packaging the application into a .intunewin file.
- Supports pre-installation, installation, and post-installation scripts.
- Offers robust detection rules based on files, registry, or PowerShell scripts.
Memory trick: Complex Apps Need Intelligent New Tools.
Intune Wi-Fi EAP-TLS Profile
Flip cardA Wi-Fi configuration profile in Microsoft Intune that configures devices to connect to WPA2-Enterprise networks using EAP-TLS for certificate-based authentication.
- Uses EAP-TLS for strong authentication.
- Requires client certificates.
- Encrypts traffic on WPA2-Enterprise networks.
- Designed for corporate security.
Memory trick: Enterprise EAP is the key to secure corporate Wi-Fi with certificates.
Intune Wi-Fi EAP-PEAP Profile
Flip cardA Wi-Fi profile configuration in Intune for iOS devices that uses EAP-PEAP for secure authentication, typically with username/password credentials (e.g., Azure AD).
- Uses a server certificate to establish a TLS tunnel.
- Authenticates user credentials (e.g., username/password) within the protected tunnel.
- Commonly used with RADIUS servers for enterprise authentication.
Memory trick: PEAP for passwords, TLS for certificates.
Intune Disk Encryption Policy
Flip cardA Microsoft Intune policy type used to manage and enforce disk encryption technologies like BitLocker on Windows devices.
- Specifically designed for BitLocker and FileVault management.
- Allows for automatic deployment and enforcement of encryption.
- Found under 'Endpoint security' in the Intune admin center.
Memory trick: Encryption's Endpoint Shield: Direct, Secure, and Ready.
Intune Custom ADMX Import
Flip cardA Microsoft Intune feature that allows administrators to upload custom Group Policy Administrative Template (ADMX) files, making their defined settings manageable through Intune configuration profiles.
- Extends Intune's management capabilities beyond built-in CSPs.
- Enables managing legacy application settings or custom OS configurations.
- Settings are configured via a custom configuration profile after import.
Memory trick: ADMX Custom: Import, Profile, Control.
Intune iOS LOB App Deployment
Flip cardAn Intune application type used to deploy custom, internally developed iOS applications packaged as .ipa files directly to managed iOS devices, bypassing the public App Store.
- Used for custom, internal iOS apps.
- Requires the app to be packaged as an .ipa file.
- Allows automatic installation on corporate-owned devices.
- Does not rely on the public Apple App Store.
Memory trick: LOB apps are for special, in-house iOS needs.
Intune Line-of-Business App (Windows)
Flip cardAn Intune application type used to deploy traditional Windows applications (e.g., MSI, APPX, APPXBUNDLE) directly to managed Windows devices.
- Supports direct upload of installation files (e.g., MSI).
- Enables silent installation and uninstallation.
- Suitable for custom or internal applications not available in public stores.
Memory trick: Windows App: MSI's LOB is direct, Win32 for complex.
Intune PowerShell Scripts Policy
Flip cardThe PowerShell scripts policy in Microsoft Intune allows administrators to deploy and run custom PowerShell scripts on Windows devices, providing options for execution context (user/system), frequency, and detailed reporting.
- Dedicated feature for script deployment.
- Supports running with administrative privileges.
- Provides detailed success/failure reporting in Intune.
Memory trick: PowerShell Scripts: The direct line for custom commands.
Intune BitLocker Key Escrow
Flip cardThe process by which BitLocker recovery keys for Intune-managed devices are automatically backed up and stored securely in Azure Active Directory.
- Automated key storage.
- Keys stored in Azure AD device object.
- Requires appropriate Azure AD permissions to retrieve.
Memory trick: Azure AD holds the keys to the BitLocker kingdom for Intune devices.
Intune LOB App Deployment (iOS)
Flip cardThe Line-of-business (LOB) app deployment method in Microsoft Intune allows administrators to distribute custom, in-house developed applications (e.g., .IPA files for iOS) directly to managed devices.
- Used for apps not in public app stores.
- Requires the app package file (.IPA for iOS, .APK for Android, .MSI/.EXE for Windows).
- Enables direct control over app distribution for internal applications.
Memory trick: LOB: For Your Own Private App Store.
Intune Custom Profile (OMA-URI)
Flip cardA Microsoft Intune configuration profile that allows administrators to deploy custom settings to devices using Open Mobile Alliance Uniform Resource Identifier (OMA-URI) paths, directly interfacing with Configuration Service Providers (CSPs).
- Used for settings not exposed in Intune's built-in templates.
- Requires knowledge of CSPs and their OMA-URI paths.
- Provides granular control over device configurations.
Memory trick: Custom Options Make Administration Unique.
Intune iOS/iPadOS Update Policies
Flip cardA Microsoft Intune feature that allows administrators to manage and control the deployment of iOS/iPadOS operating system updates on supervised and managed devices.
- Allows deferring updates for a specified period.
- Enables scheduling forced update installations.
- Requires devices to be supervised for full control.
Memory trick: Device OS: Update Policies Directly Lead.
Intune iOS Wi-Fi Profile
Flip cardA Microsoft Intune configuration profile type used to deploy pre-configured Wi-Fi network settings to iOS/iPadOS devices, ensuring consistent and secure network access.
- Supports various security types (WPA/WPA2 Personal, Enterprise, Open).
- Can include proxy settings, EAP types, and certificates.
- Prevents users from modifying the deployed network settings.
Memory trick: Wi-Fi Profile is the 'network engineer' for your iOS devices.
Intune Endpoint Security Disk Encryption
Flip cardIntune Endpoint security policies, specifically the 'Disk encryption' profile type, provide a dedicated and simplified interface for configuring BitLocker on Windows devices, including recovery key escrow to Azure AD.
- Dedicated policy type for BitLocker management.
- Configures encryption, PIN/password requirements, and key escrow.
- Streamlines deployment compared to custom profiles.
Memory trick: Endpoint Security: Encrypting Disks and Escrowing Keys.
Intune Wi-Fi Profile
Flip cardA Microsoft Intune configuration profile used to automatically provision Wi-Fi network settings, including SSID, security type, and authentication details, to managed devices.
- Supports various security types (WPA2 Personal, WPA2 Enterprise).
- Can integrate with certificate profiles for EAP-TLS authentication.
- Simplifies network access for end-users.
Memory trick: Networks Securely Connect Through Intune's Power.
Intune macOS Wi-Fi Profile
Flip cardAn Intune configuration profile type for macOS used to deploy detailed Wi-Fi network settings, including SSID, security type (e.g., WPA2 Enterprise), and authentication methods (e.g., EAP-TLS with certificates).
- Dedicated profile type for Wi-Fi configurations.
- Supports various security types, including 802.1X.
- Can integrate with certificate profiles for EAP-TLS.
- Ensures consistent network access for managed macOS devices.
Memory trick: Wi-Fi profiles connect Mac devices securely.
Intune LOB App (iOS)
Flip cardA Microsoft Intune application type used to deploy custom, in-house developed iOS applications packaged as .ipa files directly to managed iOS/iPadOS devices.
- Requires the .ipa file to be uploaded to Intune.
- Used for apps not available in the public Apple App Store.
- Deployment is managed directly by Intune, bypassing the App Store.
Memory trick: iOS Apps Deliver Easily Through Intune.
Intune iOS App Source Restriction
Flip cardAn Intune device restriction setting for iOS that controls whether users can install applications from sources other than the official Apple App Store.
- Enhances device security.
- Prevents sideloading of apps.
- Ensures apps are vetted by Apple.
Memory trick: Only trusted developers can build in my walled App Garden.
Windows Autopilot
Flip cardA collection of technologies used to set up and pre-configure new Windows devices, enabling automatic enrollment into Intune and transforming the Out-of-Box Experience (OOBE) into a streamlined, zero-touch deployment.
- Simplifies OOBE for new devices.
- Enables automatic Intune enrollment.
- Requires devices to be registered with Autopilot service.
- Reduces IT overhead for device provisioning.
Memory trick: Autopilot guides new devices to their Intune home.
Intune Driver and Firmware Updates
Flip cardA dedicated policy type in Microsoft Intune for managing the deployment of driver and firmware updates to Windows devices, offering more granular control than general update rings.
- Specific policy for drivers/firmware.
- Allows approval and deferral.
- Enhances device stability and security.
Memory trick: Drivers and firmware get their own VIP lane for updates.
Intune Update Rings
Flip cardA Microsoft Intune policy type used to manage the timing and behavior of Windows 10/11 quality and feature updates for managed devices.
- Configures deferral periods for both quality and feature updates.
- Controls restart behavior, including active hours.
- Allows for phased deployment by assigning different rings to groups.
Memory trick: Updates Really Need Good Control, Everywhere.
Android Enterprise Unknown Sources Restriction
Flip cardA Microsoft Intune device restriction setting for Android Enterprise that controls whether users can install applications from sources other than official app stores.
- Prevents installation of apps from non-Google Play Store sources.
- Does not restrict app installation from the Google Play Store.
- Enhances device security by limiting potentially malicious app installations.
Memory trick: Guard the gate, but let the official store deliver.
Localized Experience Packs (LXPs)
Flip cardModern language packs for Windows 10/11 that provide a comprehensive localized user experience, including display language, region, and keyboard layouts, simplifying global deployment and management.
- Delivered via Microsoft Store or LXP ISO.
- Replace older MUI and LIP packs.
- Ensure a fully localized OOBE for users.
Memory trick: LXPs give you the 'Luxury Xperience' of full localization.
Microsoft Endpoint Configuration Manager (MECM)
Flip cardA comprehensive management solution for deploying operating systems, applications, and updates across a large enterprise, offering extensive control and reporting for on-premises IT infrastructure.
- Supports custom image deployment (WIM files).
- Provides robust task sequencing for automation.
- Offers PXE boot for bare-metal installations.
- Integrates with Active Directory and other Microsoft services.
Memory trick: MECM manages large enterprises with custom images, PXE, and task sequences.
In-place Upgrade
Flip cardA method of upgrading a Windows operating system to a newer version by running the setup from within the existing OS, preserving user data, installed applications, and system settings.
- Retains user data, applications, and settings.
- Simpler and faster than a clean installation.
- Requires the device to meet minimum hardware requirements.
- Can be performed using Windows Update, ISO, or SCCM/MDT.
Memory trick: In-place upgrade keeps everything, just updates the OS.
WUfB Driver and Firmware Update Deferral
Flip cardA Windows Update for Business policy that allows administrators to delay the installation of driver and firmware updates on managed devices for a specified number of days.
- Applies specifically to driver and firmware updates.
- Provides control over update timing for these critical components.
- Ensures automatic updates while allowing for testing/validation.
Memory trick: Defer different updates for different delays.
DISM Image Mounting
Flip cardThe process of making a Windows Imaging Format (.WIM) file accessible for offline servicing by mounting its contents to a local folder, allowing for direct modification.
- Required first step for offline WIM modification.
- Uses `DISM /Mount-Image` command.
- Allows injection of drivers, updates, and packages.
Memory trick: Mount the image, then modify.
Safe Mode
Flip cardA diagnostic startup mode for Windows that starts the operating system with a minimal set of drivers, services, and programs, making it easier to troubleshoot problems that prevent Windows from starting correctly.
- Loads only essential system services and drivers.
- Useful for diagnosing driver conflicts, malware, or corrupted software.
- Accessed via Windows Recovery Environment (WinRE) or System Configuration (msconfig).
Memory trick: Safe Mode is like putting Windows in a 'safe room' with only the bare necessities.
bootrec command
Flip cardA command-line tool available in the Windows Recovery Environment (WinRE) used to troubleshoot and repair master boot record (MBR), boot sector, and Boot Configuration Data (BCD) issues.
- Commonly used with options like /FixMbr, /FixBoot, /ScanOs, and /RebuildBcd.
- Essential for resolving boot failures caused by corrupted boot data.
- Accessed via Command Prompt in WinRE.
Memory trick: Bootrec gets your boots (boot-up) back on track.
Delivery Optimization
Flip cardA Windows feature that uses peer-to-peer technology to share Windows updates, Microsoft Store apps, and other content among devices on a local network or the internet, reducing bandwidth consumption.
- Reduces internet bandwidth usage for updates.
- Operates on a peer-to-peer basis.
- Configurable via Group Policy, Intune, or Settings app.
- Can be used for Windows updates, feature updates, and Microsoft Store apps.
Memory trick: Delivery Optimization delivers updates peer-to-peer, saving bandwidth.
Deployment Image Servicing and Management (DISM)
Flip cardA command-line tool used to service a Windows image (.WIM or .VHD) or to prepare a Windows Preinstallation Environment (WinPE) image. It can be used to add drivers, packages, features, and optimize image size.
- Core tool for offline Windows image modification.
- Adds/removes drivers, language packs, features on demand.
- Optimizes image size and repairs image corruption.
Memory trick: DISM directly services the image's inner workings.
User State Migration Tool (USMT)
Flip cardA command-line tool included in the Windows Assessment and Deployment Kit (ADK) that captures user accounts, user files, operating system settings, and application settings, and then migrates them to a new Windows installation.
- Supports wipe-and-load migrations.
- Captures and restores user profiles and data.
- Requires planning and command-line execution.
Memory trick: USMT: User State Moves Smoothly.
Microsoft Deployment Toolkit (MDT)
Flip cardA free tool from Microsoft that provides a unified console and set of tools for automating desktop and server deployment, including OS installation, application installation, and system configuration.
- Supports 'Lite Touch' and 'Zero Touch' deployments.
- Integrates with Windows ADK and MECM.
- Ideal for deploying customized images with pre-installed applications.
- Uses task sequences for automated deployment steps.
Memory trick: MDT Makes Deploying Images Delightful
System Restore
Flip cardA Windows recovery tool that allows users to revert their computer's system files, installed applications, and registry to a previous point in time (a 'restore point') without affecting personal files.
- Reverts system changes, not personal files.
- Useful for recovering from driver/software issues.
- Requires restore points to be enabled and created.
- Accessible from Advanced Startup options.
Memory trick: System Restore: Revert, Don't Hurt Data
MECM Replace Deployment
Flip cardA Microsoft Endpoint Configuration Manager (MECM) task sequence scenario designed for migrating user data and settings from an old computer to a new computer as part of an operating system deployment.
- Used when replacing old hardware with new hardware.
- Captures user state data (e.g., files, settings) from the old device.
- Deploys a new OS to the new device.
- Restores user state data to the new device.
Memory trick: Replace Old with New, Data Too!
Thin Image with Provisioning Packages
Flip cardA deployment strategy where a minimal operating system image is deployed, and then applications and settings are customized post-deployment using provisioning packages.
- Reduces image size and maintenance complexity.
- Enables flexible, department-specific customization.
- Provisioning packages are easy to create and apply.
Memory trick: Thin image, then provisioning packages for agility.
System File Checker (SFC)
Flip cardA command-line utility in Windows that scans for and restores corrupted, damaged, or missing protected system files with correct versions from the system's component store.
- Primary tool for repairing corrupted system files.
- Accessible from Windows Recovery Environment.
- Command: `sfc /scannow`.
Memory trick: SFC first for corrupted system files.
Microsoft Application Virtualization (App-V)
Flip cardA Microsoft technology that allows applications to run in a virtualized environment, isolated from the underlying operating system. This enables legacy or incompatible applications to function on newer OS versions.
- Part of Microsoft Desktop Optimization Pack (MDOP).
- Applications are 'sequenced' and streamed to clients.
- Reduces application conflicts and simplifies deployment.
- Ideal for legacy application compatibility on new OS.
Memory trick: App-V virtualizes old apps to run on new Windows 11.
DISM /Add-Driver
Flip cardA DISM command used to add specific device drivers to an offline Windows image (WIM or VHD) before deployment.
- Requires the image to be mounted first.
- Used to ensure hardware compatibility for devices not natively supported by Windows.
- Can add multiple drivers or entire driver folders.
Memory trick: To add a driver, you need the 'Add-Driver' command, simple as that.
DISM /Apply-Image
Flip cardA DISM command-line option used to deploy a Windows Imaging Format (WIM) file to a specified volume or partition on a target device, effectively installing the operating system.
- Installs a WIM image onto a hard drive.
- Requires specifying the image file, index, and apply directory.
- Often used in conjunction with Unattend.xml answer files for automation.
- Typically part of a larger deployment script or task sequence.
Memory trick: Apply-Image puts the OS package onto the PC.
Reset this PC (Keep my files)
Flip cardA Windows recovery option that reinstalls the operating system while preserving personal files, but removes installed applications and drivers.
- Reinstalls Windows, resolves system corruption.
- Keeps personal user files.
- Removes installed applications and drivers.
Memory trick: Reset PC: Keep files, fix the problem.
Windows Upgrade Rollback Period
Flip cardThe default time (10 days) after a Windows feature upgrade during which a user can revert to the previous version of the operating system, which can be extended via policy.
- Default period is 10 days.
- Can be extended up to 60 days via Group Policy or MDM.
- Requires the 'Windows.old' folder to be present.
Memory trick: Rollback days: A policy to extend the safety net.
Windows Autopilot User-Driven Mode
Flip cardA cloud-based deployment method that allows end-users to set up new Windows devices with minimal IT intervention, automatically joining Azure AD and enrolling in Intune.
- Automates device provisioning for new devices.
- Requires devices to be registered with Autopilot service.
- Integrates with Azure AD and Microsoft Intune.
Memory trick: Autopilot sails new devices to the cloud, user-driven.
Windows Update for Business (WUfB)
Flip cardA cloud-based service that enables organizations to manage Windows updates directly from Microsoft, offering control over update deferrals, deployment rings, and update types for Windows client devices.
- Cloud-native, no on-premises server required.
- Manages both Quality (security) and Feature (version) updates.
- Uses deployment rings for phased rollouts.
- Configurable via Group Policy, Intune, or other MDM.
Memory trick: WUfB: Cloud-Based Updates, Business-Controlled
Windows Update for Business (WUfB) Feature Update
Flip cardA service within Windows Update that allows organizations to manage when and how Windows 10/11 feature updates (upgrades to new OS versions) are delivered to devices, often integrated with Intune for policy deployment.
- Enables automated, in-place upgrades.
- Preserves user data, applications, and settings.
- Managed via Group Policy or Intune, providing control over deployment rings and deferrals.
Memory trick: WUfB makes upgrades a 'Walk-Up-and-Be-Done' experience.
Windows Autopilot Pre-provisioning
Flip cardA feature of Windows Autopilot that allows partners or IT staff to pre-provision a Windows device, so it arrives fully configured and business-ready for the end-user, including Intune enrollment and policy application.
- Designed for new devices.
- Enables vendor/partner pre-configuration.
- Ensures device is business-ready upon user receipt.
- Automatically enrolls devices into Intune and applies policies.
Memory trick: Automated Pre-provisioning Makes Device Delivery Seamless
DISKPART
Flip cardA command-line utility in Windows for managing disk partitions, volumes, and complex disk configurations.
- Allows creating, deleting, formatting, and extending partitions.
- Can be used for both basic and dynamic disks.
- Essential for preparing drives for OS installation or data storage.
Memory trick: DISKPART: 'Disk Partitioning' is its art.
Windows.old Folder
Flip cardA folder created by Windows during an in-place upgrade that contains files from the previous operating system installation, allowing users to revert to the prior OS version if necessary.
- Essential for rolling back an OS upgrade.
- Retained for a default of 10 days (configurable up to 60).
- Deletion of this folder prevents rollback.
Memory trick: Windows.old is your 'old' friend for going back in time.
Windows Autopilot Pre-provisioning (White Glove)
Flip cardA feature of Windows Autopilot that allows partners or IT administrators to pre-provision a Windows 11 device before the end-user receives it, ensuring it's ready to use with applications and policies already installed.
- Formerly known as White Glove.
- Reduces end-user setup time significantly.
- Ideal for devices shipped directly to users from manufacturers.
Memory trick: Autopilot White Glove makes devices 'ready to fly' before they even land with the user.
WUfB Deployment Rings
Flip cardGroups of devices configured to receive Windows updates (feature and quality) at different times, allowing for phased rollouts, testing, and risk management within an organization.
- Used for phased update deployments.
- Typically includes rings like 'Pilot', 'Fast', 'Broad'.
- Configurable via Group Policy or Intune.
- Ensures early testing before wider deployment.
Memory trick: Rings Roll Out Updates, Right on Time
Windows 365 Cloud PC
Flip cardA cloud-based service that provides a full, personalized Windows 11 or Windows 10 desktop experience, streamed from the Microsoft cloud to any device.
- Bypasses local hardware requirements.
- Centralized management and security.
- Provides a consistent, high-performance experience for users anywhere.
Memory trick: When local hardware is a no-go, the Cloud PC is the way to flow.
Windows Recovery Environment (WinRE) Command Prompt
Flip cardA powerful tool accessible via Advanced Startup Options that provides a command-line interface to perform diagnostic and recovery tasks on a non-bootable Windows installation, including accessing and copying files.
- Accessible when Windows fails to boot.
- Allows interaction with file system (C: drive).
- Can use `notepad.exe` (file explorer) or `xcopy` for data recovery.
- Does not require the main OS GUI to function.
Memory trick: Command Prompt: Critical Data's Crucial Path
Legacy Application Compatibility (VMs)
Flip cardFor deeply incompatible legacy applications, running them in a virtual machine (VM) with a compatible operating system (e.g., Windows 7) on a newer host OS (e.g., Windows 11) provides the necessary isolated and compatible environment.
- Used for applications with fundamental OS incompatibilities.
- Requires a hypervisor (e.g., Hyper-V, VMware Workstation).
- Provides a fully isolated, native OS environment for the application.
- Can be managed centrally or deployed per-user.
Memory trick: Virtual Machines: The Legacy App's Last Refuge
System Restore Point
Flip cardA snapshot of your Windows system files, installed applications, Windows Registry, and system settings at a particular point in time, allowing you to revert your system to that state without affecting personal files.
- Does not affect personal data (documents, pictures).
- Can undo system changes caused by new software or drivers.
- Requires System Protection to be enabled.
Memory trick: System Restore is your time machine for system settings, preserving precious memories (files).